Earlier quoted context omitted.
They can also push new browser releases though. They are also auto-installed by default. The exception is that an addon can do slightly less damage than a compromised browser itself.
I deeply hate this update methodology. Some hippster fresh from university decides that the gui, approach, functionality i use daily is no longer needed and pushes his rewrite into a release. One click later im stuck with this, because all the bundled crap is hijacking the "security" for a ride. If any software developer would truely respect users, he would offer updates as seperate packages, where users can opt out…
At that point, it’s probably better to just stop feature development and do nothing but security patches, which of course will lead to stagnation and which will also lead to fragmentation as many more incompatible releases of the same software will be out in use.
This will make it even harder for developers to adapt new technologies. Imagine how bad the already messy caniuse.com would look when every single browser version would be supported forever and could be individually configured feature by feature.
Especially as people somewhat versed in technology (I think it’s safe to call HN audience that), I think there is advantage in going with the flow and adapting to new releases and UI paradigms.
Otherwise we'd still be running on DOS and us developers would still have to support it.
Relevant XKCD: https://xkcd.com/1172/